REF1695
REF1695 is a threat cluster tracked by Elastic Security Labs that has operated since at least late 2023, using counterfeit software installers, often packaged as ISO files, to deliver remote access trojans and cryptocurrency mining malware. The operation relies on social engineering, including ReadMe.txt instructions that persuade victims to bypass Windows SmartScreen, after which multiple malicious components are installed instead of legitimate software. Reported payloads and tooling associated with REF1695 include CNB Bot, PureRAT, PureMiner, SilentCryptoMiner, and a custom .NET-based XMRig loader. CNB Bot enables further payload injection, while the malware set provides remote access, persistence, code update capability, and cryptomining functionality. The operation is designed for long-term residence and evasion: the malware monitors for 35 security and analysis tools, including Task Manager and Wireshark, and temporarily stops mining when such tools are opened before restarting afterward. SilentCryptoMiner reportedly uses direct system calls and disables Windows Sleep and Hibernate modes. The campaign also uses the WinRing0x64.sys driver for deep processor access, abuses GitHub as a trusted payload delivery platform by hosting staged binaries on identified accounts, and uses RSA-2048 encryption for bot control. Monetization includes Monero mining and CPA fraud, with victims prompted to complete surveys or trial sign-ups to unlock registration keys; researchers identified four Monero wallets linked to the operation that collected more than 27.88 XMR. No additional aliases or sub-groups are directly mentioned in the provided content.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
Observables
36 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Runs a cryptomining and CPA fraud campaign using fake software installers and ISO files, deploying remote access and mining malware while maintaining long-term persistence and evading detection.
Uses counterfeit installers and ISO lures to deliver remote access trojans and cryptocurrency mining malware, including staged payload delivery via GitHub-hosted binaries.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.